From: Pirch H. <pir...@ya...> - 2003-11-21 03:00:32
|
Title 22/2/2003SquirrelMail Proxies IMAP Vulnerability SummarySquirrelMail is a standards-based webmail package written in PHP4. A vulnerability in IMAP that allows viewing of arbitrary files also manifests itself in SquirrelMail, as SquirrelMail does not block the vulnerability. DetailsThe vulnerability is not in the SquirrelMail itself, but rather in the IMAP daemon. However, some administrator would like to believe that since they are not exposing the IMAP to the Internet they do not need to close this particular security hole (the hole that allows viewing of arbitrary files). But as you can see in the examples below, SquirrelMail will happily proxy the IMAP's vulnerability to an external attacker. Exploit: http://127.0.0.1/some_link/src/search.php?mailbox=%2Fetc%2Fpasswd&what=root&where=BODY&submit=Search (Replace 'Search' by the word for search in your language) Or simply by entering: http://127.0.0.1/some_link/src/read_body.php?mailbox=%2Fetc%2Fpasswd&passed_id=1&startMessage=0&show_more=0&pos=0&where=BODY&what=root Vendor response: Thank you for detailing the vulnerability. However, I'm almost positive that the issue you're reporting is essentially a vulnerability in your IMAP server. I cannot reproduce it here, and I checked and the parameters are passed directly to the IMAP server. I dare say that by telneting to your IMAP server and using the same strategy, you will be able to retrieve the password file just as well. This proves that the issue is not SquirrelMail-related at all, even more, can't be solved by SquirrelMail. - Thijs Kinkhorst University of Washington's IMAP server is popular for being able to read files it just should not have access to. You might want to check what IMAP server you're using, and check the documentation. I'm not able to replicate this issue in any way with Courier-IMAP. University of Washington has this documented over at their website: http://www.washington.edu/imap/IMAP-FAQs/index.html#5.1 - Jonathan Angliss Additional informationThe information has been provided by riadh said. ______________________________________________________ Hi i'm Pirch I search this article on the web and I want to ask if it is true? I'm new user of Squirrelmail and I want to insure that my system is free from the vulnerability. Please reply to this e-mail. Thanks and More Power to Squirrelmail Pirch _______________________________________________________ Reference: http://www.securiteam.com/unixfocus/5XP0N0095W.html --------------------------------- Do you Yahoo!? Protect your identity with Yahoo! Mail AddressGuard |